|
Important new Oracle patches
released
In this article we see an announcement of important new patches for
Oracle:
http://www.oracle.com/technology/deploy/security/pdf/cpuapr2005.pdf
This SearchSecurity articles notes some important issues with this
Oracle patch release:
http://searchsecurity.techtarget.com/originalContent/0,289142,sid14_gci1079301,00.html
This article includes an important risk matrix for Oracle security
vulnerabilities.
"The Critical Patch Update issued [today] contains fixes for
security vulnerabilities in the Oracle Database, Oracle Application
Server, Oracle Enterprise Manager Grid Control and Oracle E-Business
Suite," said an Oracle spokesperson. "The patch also includes fixes
that customers are likely to apply and/or are prerequisites for the
security fixes."
There is also a MOSC note:
http://MOSC.oracle.com/MOSC/plsql/ml2_documents.showDocument?p_database_id=NOT&p_id=304410.1
The company noted more than 89 security vulnerabilities -- many of
them cumulative -- in its new threat matrix that measures the ease
of exploitability and its impact. Oracle said the supported product
releases and versions affected include:
- Oracle Database 10g Release 1, versions
10.1.0.2, 10.1.0.3, 10.1.0.3.1, 10.1.0.4 (10.1.0.3.1 is
supported for Oracle Application Server only);
- Oracle9i Database Server Release 2,
versions 9.2.0.5, 9.2.0.6;
- Oracle9i Database Server Release 1,
versions 9.0.1.4, 9.0.1.5, 9.0.4 (9.0.1.5 FIPS) (all of which
are supported for Oracle Application Server only);
- Oracle8i Database Server Release 3,
version 8.1.7.4;
- Oracle Application Server 10g Release 2
(10.1.2);
- Oracle Application Server 10g (9.0.4),
versions 9.0.4.0, 9.0.4.1;
- Oracle9i Application Server Release 2,
versions 9.0.2.3, 9.0.3.1;
- Oracle9i Application Server Release 1,
version 1.0.2.2;
- Oracle Collaboration Suite Release 2,
versions 9.0.4.1, 9.0.4.2;
- Oracle E-Business Suite and Applications
Release 11i, versions 11.5.0 through 11.5.10;
- Oracle E-Business Suite and Applications
Release 11.0;
- Oracle Enterprise Manager Grid Control
10g, versions 10.1.0.2, 10.1.0.3;
- Oracle Enterprise Manager versions
9.0.4.0, 9.0.4.1;
- PeopleSoft EnterpriseOne Applications,
versions 8.9 SP2 and 8.93;
- PeopleSoft OneWorldXe/ERP8 Applications,
versions SP22 and higher.
However, one expert noted that many flaws weren't addressed in the
patch, including a SQL injection vulnerability in default
installations of Oracle Forms found by bug researcher Alex Kornburst.
|
|